damn spyware
Miscellaneous Forums/General Discussion/damn spyware
got a home page hijack thing. i have tried everything, including messing with the registry.
so yeah I open my browser and get this
http://www.syserrors.com/instead of my usual google home page. I managed to fix the greyed out internet options, but I still get redirected.
Man i would love to meet these people
Anyone had this and got a solution.
I have tried all the antivrus /spyware stuff inlcluding adaware/spybot etc
Are you using IE? If so, how about switching to Firefox, Opera or anything else than IE?
yeah i could , but i am bugged that i can't fix IE. I am taking it personally
Nobody can fix IE. It's intentional.
Using IE and then complaining about a virus, spyware or other malicious things is like having unprotected sex with a prostitute and then complaining because you caught something nasty. What did you expect to happen?
well..Ruz..I do agree with you...I would like to meet these peoples too..by the way, try XoftSpy..its really good..
Changing browser may not solve the problem. To use the above example, it's like putting the condom on afterwards.
For your homepage to be changed a program of some kind has to be run, it could be an event launched by loading IE but more likely it's a memory resident program as most browser hijacking is.
Memory resident programs can be a problem, because they often do more than just change your homepage. You may have adware or a virus, but whatever it is, it's malware.
Try the usual adware removal tools and if you use one a virus checker, but most importantly of all check your task manager and put the task names into google/altavista and check them to make sure all the tasks running are things you want to be running.
Startup programs can be in a number of places, but most likely is in one of the various registry "Run" sections. If you have multiple user logins configured you may have to search several sections of the registry to check all "Run" folders.
Also dont overlook the easy things like the start menu "startup" folder (which I did once to my dismay!).
Pre-XP Windows can also use win.ini and the autoexec.bat to launch malware, look for shell= run= in win.ini and in autoexec.bat remove any command line operators after "Win" if present.
EDIT: shell= should say explorer.exe (although changing it to progman.exe can be quite a fun thing to do to OTHER peoples PC's ;) ).
You may want to check your task manager to see if any unknown tasks are running. If there's a program running that's changing your system every 5 minutes or so, any amount of registry changes against that software will be undone on you.
If you can't figure out what's causing the problems, just start shutting programs down. The worst that can happen is your PC crashing, which resetting will undo. One thing or another may quit working, but you'll then know what that process is for. :)
you may also want to check out Microsoft antispyware Beta.
Also, make sure to run spybot/adaware/antispyware in *safe* mode, certain things won't be removable if they have resident processes in memory.
Also make sure not to start IE before running your checks, even in safemode -- IE will autopmatically load its plugin 'helper' modules, which likely start your spyware processes.
xoft spy is great, I second that :)
CrapCleaner <- google is your friend.
Also, since this is a homepage-hijack -- there's a good chance that you have CoolWebSearch, which is notoriously difficult to remove. Most of the popular anti-spyware programs will remove 'most' of CWS, but not everything.
There's a free program called cwshredder, now owned by Trend Micro, that will remove all the last traces of its various incarnations... check it out.
I recommend MS Antispyware too... not only can you set all your internet options back to their defaults (or memorise customised defaults) but it's realtime protection ensures it can't be changed again, even if there is crap running on your system it doesn't detect...
My favourite malware removal tool is still FORMAT.COM. Just make sure you download your OS patches first and install them before you go online - or have a firewall to protect you from the worms while you download them.
I ought to get a copy of Norton Ghost at some point to make it even faster. I swear half the time I spend is going through TweakUI trying to get things exactly how I like them.
If you do sort this problem out, please be sure to reply with how you removed the spyware/adware/virus thanks.
Another reason why I like my Zone Alarm Security Suite ... no virus and spyware problems at all, they already die before reaching my system ;-)
As well as P2P connections...
Is the M$ anti-spyware still marking the Claria Corp(GATOR and such) software as safe?
If so... I would use something else.
There was a big hoohah about it here in the UK Computer Press.
some links
http://www.eweek.com/article2/0,1895,1834607,00.asphttp://www.edbott.com/weblog/archives/000817.htmlCheers
Garion
I installed Panda Platinum 2006 the other day (for a laugh). Whilst it is really good software, I'll be uninstalling it again soon. After years of having no AV software installed, I still haven't managed to contract a virus.
Guess I'm just careful.
BTW, if you are rich, I'd recommend you buying Panda Platinum (it is exceptionally expensive).
I got my IE hijacked a couple of months ago and SpySweeper seemed to help...
I'm using FireFox now, though! ;-)
FireFox is all well and good, but seems a bit 'faddish' to me. Just because everyone has heard 'FireFox is better and you don't get spyware' they blindly download it.
Opera is a better browser than FireFox.
I admit, I've got Opera, FireFox, NetScape and IE installed. This is because I had delusions of web development in the not too distant past (I can 'do' PHP).
yeah i ended up using firefox in the end. I got my security updates and such . should be ok now. i may just reinstall my os anyway.
Yeah ie is just pants as it is targetted the most. Tut tut about the updates...
well i hadn't had this particular pc connected to the net for about 2 years, so i was a bit careless really.
Odd though, i have never had any problems before
Is the M$ anti-spyware still marking the Claria Corp(GATOR and such) software as safe?
I'm not sure. Claria/GAIN stuff is usually clearly marked, so I'm not silly enough to click OK ;] But I've found that the program always asks me what actions to take when it does notice something amiss... Usually provides a recommendation from SpyNet, but never actually does anything by itself until I've given it the same response for the same particular nastiness twice.
Claria is detected, but the default action is set to leave it in place -- since Microsoft acquired Claria.
Actually, no that would probably still be the case, you're right, I remember now that it never blocks something without your permission, but there are plenty of times where it will let stuff through. It always pops up and tells you that it's doing it though.
Toby, what was you nick before I've just totally forgotton it and ca't get a "handle" on you any more?
Hotcakes mostly up until this year where I've decided to change it regularly, then a few things here and there, a popular one was Help me I'm upside down for a little while (except spelt upside down) but the one I think you want to know of is Not a Noodle Cowar[d]. I mean Vanilla.
Oh yeah Hotcakes the Nag/Alias, Vanilla fine, handle restored.
So, when's Max3D due?
... while you are answering 'personal questions' Toby - what is the something that you are 'now actually good for' ? I just get an internal error on that link.
The link works for me, but I think it failed in the past. I know! it's because I've bought blitz max and registered it. BlackJ are you BlitzPlus and 3D only?
Yeah, it doesn't work for me and I don't have BMax.
I think it's hell funny. Good for something, apparently, yet the link to it doesn't even work. Funny as fried cabbage.
I know how to fix it now though. Maybe. Try it again! =]
BTW. not sure if it was already said:
Quote:
>>Changing browser may not solve the problem. To use the above example, it's like putting the condom on afterwards.<<
Not to change the browser would be like refusing to use condoms, even after some real bad experience.
Well, the guy could go celebit and just not visit those nasty sites anymore.
Hey, isn't it a blatant conflict of interest MS Antispyware treats a MS owned company (Claria) as completely harmless?
Tracked down the oproblem , but the smegegr still won't gop away.
the file nvctrl.exe seems to be a trojan or so |i read, but even though i have dleted that, the browser still points to the same damn homepage
C:\WINDOWS\System32\mssearchnet.exe
C:\WINDOWS\System32\mscornet.exe
C:\WINDOWS\System32\kernel32.dll
C:\WINDOWS\System32\nvctrl.exe
C:\windows\system32\1024
C:\WINDOWS\system32\hpDF5.tmp
C:\WINDOWS\SYSTEM32\slcpappl.cpl
This is the stuff I got rid of
Actually it came back even though i deleted most of them, but tried again and now its fixed.
Yeah if you have any of these files I suggest you get rid of em.
I had to use kilbox to get rid of them permanently
Hijack this
EMCO Malware Bouncer
AdAwareSE
and
MS Antispyware Beta
AND you have to run ALL of them to get MOST of whats out there...
Huh? C:\WINDOWS\System32\kernel32.dll ?? You say this can be removed? Thought this is a vital OS library? Or do you mean I should replace it by the original one?
I understood you could destroy a good portion of your WinXP install and all that would happen is a little window pop-up saying "shove your original XP disc in because your files are all buggered".
I think the popup said that, but it might have been worded a little differently.
No, that's pretty much right ;]
I understood you could destroy a good portion of your WinXP install and all that would happen is a little window pop-up saying "shove your original XP disc in because your files are all buggered".
Hmmm the American version has a slightly different grammatical feel to it...
;)
But Vinylpusher is essentially right!
RZ
Opera is a better browser than FireFox.
Opera takes longer to load than firefox :)
That must make Netscape the king of all browsers then.
the free online malware sweeper at Trend Micro is worth a look, especially as Adaware and Msanti.etc are not free...
http://housecall.trendmicro.com/and yes, I agree that Format.com is a pretty good solution if all else fails, if not Ghost, PowerQuest Drive Image is easy and reliable.
Just build your perfect system, clone it, and the re-install is the work of 10 minutes. Handy for those who "try" 20 new shareware proggies a week :)
Adaware and Msanti.etc are not free...
Yes they are. MSAnti.etc actually has free the features you pay for in Adaware.